Impact
The vulnerability is a use‑after‑free flaw in the Chrome printing subsystem that enables a remote attacker to craft an HTML page that may escape the browser's sandbox. By exploiting the memory corruption triggered when processing the malicious page, an attacker could potentially gain full control over the victim's machine, violating confidentiality, integrity, and availability.
Affected Systems
GOOGLE:CHROME versions prior to 149.0.7827.103 are affected. This includes all desktop builds of the stable channel that have not yet received the patch referenced in the Google Chrome release notes.
Risk and Exploitability
The CVE does not report an EPSS score and is not listed in the CISA KEV catalog, but the CVSS score is 9.6, indicating a critical level of severity. The likely attack vector involves a remote attacker delivering a crafted HTML page that the victim opens or otherwise causes the browser to load. Because the flaw resides in the printing path, normal browsing alone does not trigger exploitation unless the attacker causes the browser to print a page. No public exploit is documented, but the high severity and lack of mitigations in earlier Chrome releases suggest a significant risk for exposed systems.
OpenCVE Enrichment